$OpenBSD: patch-pki_generate_ca,v 1.2 2016/01/28 17:15:03 kspillner Exp $

Fix CA certificate generation for GNUTLS v3.3.20 and later.
When this option was present clients failed to validate the
server's certificate when trust=strict with "certificate
violates signer's constraints" errors.
--- pki/generate.ca.orig	Wed Jan 20 09:43:57 2016
+++ pki/generate.ca	Wed Jan 20 09:44:09 2016
@@ -26,7 +26,6 @@ country = $COUNTRY
 state = $STATE
 locality = $LOCALITY
 ca
-cert_signing_key
 EOF
 
 $CERTTOOL \
